The Cisco CCIE Security (v6.0) Practical Exam is an eight-hour, hands-on exam that requires a candidate to plan, design, deploy, operate, and optimize network security solutions to protect your network.
Candidates are expected to program and automate the network within their exam, as per exam topics below.
The following topics are general guidelines for the content likely to be included on the exam. Your knowledge, skills and abilities on these topics will be tested throughout the entire network lifecycle, unless explicitly specified otherwise within this document.
The exam is closed book and no outside reference materials are allowed.
1.0 Perimeter Security and Intrusion Prevention
1.1 Deployment modes on Cisco ASA and Cisco FTD
1.2 Firewall features on Cisco ASA and Cisco FTD
1.3 Security features on Cisco IOS/IOS-XE
1.4 Cisco Firepower Management Center (FMC) features
1.5 NGIPS deployment modes
1.6 Next Generation Firewall (NGFW) features
1.7 Detect, and mitigate common types of attacks
1.8 Clustering/HA features on Cisco ASA and Cisco FTD
1.9 Policies and rules for traffic control on Cisco ASA and Cisco FTD
1.10 Routing protocols security on Cisco IOS, Cisco ASA and Cisco FTD
1.11 Network connectivity through Cisco ASA and Cisco FTD
1.12 Correlation and remediation rules on Cisco FMC
2.0 Secure Connectivity and Segmentation
2.1 AnyConnect client-based remote access VPN technologies on Cisco ASA, Cisco FTD, and Cisco Routers.
2.2 Cisco IOS CA for VPN authentication
2.3 FlexVPN, DMVPN, and IPsec L2L Tunnels
2.4 Uplink and downlink MACsec (802.1AE)
2.5 VPN high availability using
2.6 Infrastructure segmentation methods
2.7 Micro-segmentation with Cisco TrustSec using SGT and SXP
3.0 Infrastructure Security
3.1 Device hardening techniques and control plane protection methods
3.2 Management plane protection techniques
3.3 Data plane protection techniques
3.4 Layer 2 security techniques
3.5 Wireless security technologies
3.6 Monitoring protocols
3.7 Security features to comply with organizational security policies, procedures, and standards BCP 38
3.8 Cisco SAFE model to validate network security design and to identify threats to different Places in the Network (PINs)
3.9 Interaction with network devices through APIs using basic Python scripts
3.10 Cisco DNAC Northbound APIs use cases
4.0 Identity Management, Information Exchange, and Access Control
4.1 ISE scalability using multiple nodes and personas.
4.2 Cisco switches and Cisco Wireless LAN Controllers for network access AAA with ISE.
4.3 Cisco devices for administrative access with ISE
4.4 AAA for network access with 802.1X and MAB using ISE.
4.5 Guest lifecycle management using ISE and Cisco Wireless LAN controllers
4.6 BYOD on-boarding and network access flows
4.7 ISE integration with external identity sources
4.8 Provisioning of AnyConnect with ISE and ASA
4.9 Posture assessment with ISE
4.10 Endpoint profiling using ISE and Cisco network infrastructure including device sensor
4.11 Integration of MDM with ISE
4.12 Certificate-based authentication using ISE
4.13 Authentication methods
4.14 Identity mapping on ASA, ISE, WSA, and FTD
4.15 pxGrid integration between security devices WSA, ISE, and Cisco FMC
4.16 Integration of ISE with multi-factor authentication
4.17 Access control and single sign-on using Cisco DUO security technology
5.0 Advanced Threat Protection and Content Security
5.1 AMP for networks, AMP for endpoints, and AMP for content security (ESA, and WSA)
5.2 Detect, analyze, and mitigate malware incidents
5.3 Perform packet capture and analysis using Wireshark, tcpdump, SPAN, ERSPAN, and RSPAN
5.4 DNS layer security, intelligent proxy, and user identification using Cisco Umbrella
5.5 Web filtering, user identification, and Application Visibility and Control (AVC) on Cisco FTD and WSA.
5.6 WCCP redirection on Cisco devices
5.7 Email security features
5.8 HTTPS decryption and inspection on Cisco FTD, WSA and Umbrella
5.9 SMA for centralized content security management
5.10 Cisco advanced threat solutions and their integration: Stealthwatch, FMC, AMP, Cognitive Threat Analytics (CTA), Threat Grid, Encrypted Traffic Analytics (ETA), WSA, SMA, CTR, and Umbrella
IT Training Videos and Webinars
Find hundreds of free training videos from across the technology spectrum and register for upcoming live webinars too. Start Learning
Cisco Certifications Podcast
Hear from Cisco Certifications Program Manager Yusef Bhaiji as he discusses the latest enhancements to the Cisco Certifications program. Listen Now
Webinars with Wendell Odom
Sign up for live webinars with best selling Cisco Press author, Wendell Odom. These sessions will help you prepare for the CCNA Exam which will be available Feb 24, 2020. Register Now
If you are thinking about or actively pursuing a certification, please read about latest program changes. Read Now
Evolution of Cisco’s professional certification program embraces network professionals and software developers into one community. Learn More
A supportive place on the Cisco Learning Network where you can ask questions and share ideas with other members as you prepare for your CCIE Certification. Join Now